PT-2026-4295 · Incus+2 · Incus+2

Rmcnamara-Snyk

·

Published

2026-01-01

·

Updated

2026-05-12

·

CVE-2026-23954

CVSS v3.1

8.7

High

VectorAV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Incus versions 6.21.0 and below IncusOS (affected versions not specified)
Description Incus is a system container and virtual machine manager. A flaw exists where a user capable of launching containers with custom images (e.g., a member of the ‘incus’ group) can leverage directory traversal or symbolic links within the templating functionality to achieve arbitrary file read and write access on the host system. This can ultimately lead to arbitrary command execution on the host. Specifically, when an image utilizes a metadata.yaml file containing templates, the source and target paths are not adequately validated for symbolic links or directory traversal. This allows an attacker to read arbitrary files from the host filesystem and write files to arbitrary locations, potentially overwriting critical system files. Exploitation on IncusOS requires a minor modification to the stage2 process. The vulnerability allows a user to read arbitrary files from the host filesystem and write files to the host filesystem as root.
Recommendations For Incus versions 6.21.0 and below, apply a fix as it becomes available. For IncusOS, apply a fix as it becomes available.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2026-00871
CVE-2026-23954
GHSA-7F67-CRQM-JGH7
GO-2026-4357
OPENSUSE-SU-2026:10280-1
SUSE-SU-2026:0403-1

Affected Products

Incus
Incusos
Red Os